Intel

AIKIDO-2026-859281

cxf-rt-transports-jms is vulnerable to Improper Input Validation

Improper Input ValidationCVE-2026-50632 Published Jun 15, 2026

81

High Risk

This Affects:

JAVAcxf-rt-transports-jms
0.0.0 - 4.1.6
Fixed in 4.1.7
4.2.0 - 4.2.1
Fixed in 4.2.2
Are you affected? Scan for Free

TL;DR

A further incomplete fix for CVE-2026-44417 leaves additional JNDI validation gaps in Apache CXF JMS configuration handling. If untrusted users can supply JMS or JNDI settings, attacker-controlled environment properties or URL-style JNDI names can still reach unsafe lookup paths and may lead to remote code execution.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and if untrusted users are allowed to configure JMS for Apache CXF.

Background info

cxf-rt-transports-jms is vulnerable to Improper Input Validation in versions 0.0.0 - 4.1.6 and 4.2.0 - 4.2.1.

How to fix this

Upgrade the org.apache.cxf:cxf-rt-transports-jms library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform